Privacy Policy
Effective as of 2026-09-02
Overview
CupThread is a feedback platform for app developers, built and operated by Lex Tang (“I”, “me”). This policy explains what the Service collects and how it is used. It covers two audiences:
- Developers — my customers, who register workspaces and apps in the console.
- End users — the users of my customers’ apps, who submit feedback, vote on feature requests, or read changelogs through the SDKs and public pages.
Data I collect
Developer accounts. When you sign in (via my identity provider, Clerk) I process your name, email address, and workspace membership. Billing is handled by Polar.sh as merchant of record; I never see or store your card details.
End-user feedback. Feedback and feature requests submitted through the Service may include: an anonymous device token (a random UUID), an optional name and email or social-login identity, device and app information (platform, OS, app version, build number), attached screenshots or files, votes, and — if the user opts in — an email address for changelog notifications.
End-user attributes. Developers may report attributes about their own users (such as revenue signals) to help prioritize feedback. Developers are responsible for having a lawful basis and making the required disclosures to their users before sending me this data.
Operational data. Request logs and aggregated usage metrics (for example, submission counts per workspace) used to operate and secure the Service.
How I use data
- To provide the Service: storing, displaying, and delivering feedback and roadmaps.
- To forward submissions to destinations developers configure (for example, GitHub Discussions).
- To send transactional and notification emails (changelog subscriptions, developer notifications).
- To enforce plan limits, prevent abuse, and comply with legal obligations.
I do not sell personal data, and I do not use end-user data for advertising.
Service providers
I rely on these third parties to operate the Service:
- Cloudflare — hosting, database (D1), file storage (R2), image processing, and CDN.
- Clerk — developer and optional end-user authentication.
- Polar.sh — payment processing and subscription management.
- GitHub — delivery of feedback to repositories configured by developers.
- Resend — transactional email delivery.
- Google Analytics (Google LLC) — aggregate product flow and website traffic measurement (subject to explicit user consent).
Each provider has its own privacy policy governing any data they receive.
Network endpoints
The following summarizes the endpoints the Service and its clients may contact:
| Endpoint | Who contacts it | Purpose |
|---|---|---|
| CupThread API (Cloudflare Workers) | SDKs, public pages, console | All feedback, voting, roadmap, changelog, and upload traffic. |
| clerk.* | Console, optional end-user sign-in | Authentication only. |
| polar.sh | During checkout and billing | Payments and the customer portal. |
| github.com | Only when a developer forwards feedback | Creating discussions in the developer's repository. |
| Linear / Notion / Slack APIs | Only during developer-initiated imports | Reading feedback to import. |
| api.resend.com | Server-side only | Sending changelog and notification emails. |
| googletagmanager.com / *.google-analytics.com | Browser (with explicit consent only) | Optional product flow & aggregate traffic measurement (14-month retention; no PII, feedback content, or tenant IDs). |
Analytics scripts are loaded strictly under Basic Consent Mode: before explicit consent is granted or if rejected, no Google Analytics or Google tag scripts are loaded, no cookies are created, and no cookieless pings are transmitted.
Cookies and local storage
I do not use advertising trackers or cross-site tracking. The Service stores essential values locally: your theme preference, selected language, session authentication tokens (via Clerk), and — for end users — the anonymous device token generated by the SDK.
When you interact with the analytics consent prompt, your choice is stored in a first-party cookie (ct_consent_v1, 180-day retention). If and only if you grant analytics consent, aggregate measurement cookies (such as _ga, ct_main_*, or ct_portal_*) are set for a maximum retention period of 14 months.
You can change your preferences or withdraw consent at any time using the “Preferences” link in the footer or settings. Withdrawing consent immediately deletes analytics cookies and halts further data collection.
Retention and deletion
Data is retained while the workspace it belongs to is active. Deleting an app, its feedback, or the workspace removes the corresponding content from the active database; backups and logs may persist briefly. End users may request deletion of their feedback or subscription by contacting the app’s developer or me directly.
Your rights
Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, export, or delete personal data I process, and to object to or restrict certain processing. To exercise these rights, contact me through the link below. If you are an end user, include the name of the app you used so I can locate the data.
Security
I use commercially reasonable measures to protect any data collected. However, no method of transmission over the internet or electronic storage is 100% secure, so I cannot guarantee absolute security.
Children's privacy
The Service is not directed at children under 13. I do not knowingly collect personal information from children. If you believe a child has provided personal information, please contact me so I can delete it.
Developer responsibilities
Developers act as the controllers of their end users’ feedback data. Before embedding the SDKs or public pages in an app, link this policy and disclose what is collected — including the anonymous device token and any attributes you report. You are responsible for lawful processing in your jurisdiction.
Changes to this policy
I may update this policy from time to time. I will post changes on this page and update the effective date above.
Questions about this document? [email protected].